Overview
About vulnerability
An attacker who can set thefile_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory.
Details
- Affected product:
- Spring
- Affected packages:
- Spring Integration @ 6.4.9 (+570 more)